Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: win2k, XP deletes somename_files when somename.html deleted

Re: win2k, XP deletes somename_files when somename.html deleted

From: Albert N. Umerov <bert_umerov_at_bluebottle.com>
Date: Mon, 07 Feb 2005 22:46:45 +0300

Hello,

> create a file named foobar.html
> create a folder named foobar_files
> copy a bunch of files (of any type) inside foobar_files
instead "copy" create for "foobar_files" junction (hard link) to
"c:\windows\system32" (for example)
> delete foobar.html
If user who want delete "foobar.html" have admin rights...
Simple bomb :))

> Even if there's no vuln as such, it's something to be aware of.
don't use Explorer to delete files, restrict policy to use another file
manager to delete files (for example, Far) :)))

--
Best regards,
   Albert N. Umerov
Received on Feb 07 2005
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos